SOC 2
Type II · 2026-Q1
Every claim on this site has receipts. Audit chain, GDPR posture, EU AI Act register, certifications, sub-processors — all in one place.
Each certification below has a current report or attestation. We'll send the artifacts under NDA.
Type II · 2026-Q1
Certified · BSI
EU controller-of-record
High-risk register live
BAA available
Qualified timestamps
Each transformation appends a SHA-256-signed entry. The root is anchored daily to a qualified eIDAS timestamp authority.
Where each regime fits in. Each entry has a contact at AVA Research who owns the controls behind it.
Controller-of-record + DPA on request. Right-to-erasure cascades to derivatives. EU-only data residency by default.
Annex III high-risk register live. Reviewer attribution and rationale on every automated decision. Public summary opt-in.
BAA available on Industry. Safe Harbor + Expert Determination engines. PHI access logged with reason-codes.
ICT third-party register pre-validated. Operational resilience tests quarterly. Incident reporting templates included.
Type II for Security and Availability. Report under NDA. Continuous monitoring + manual quarterly review.
Certified by BSI. SoA on request. ISMS reviewed annually. Annex A controls mapped to internal policies.
Updated 2026-Q2. Subscribe to changes via the DPA addendum.
DPA, SOC 2 Type II report, ISO 27001 certificate, sub-processor change feed. We send the bundle under NDA — usually same-day.